CVE-2017-3401
published 2017-01-27CVE-2017-3401: Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are…
PriorityP343high8.2CVSS 3.0
AVNACLPRNUIRSCCHILAN
EPSS
1.25%
65.8th percentile
Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle E-Business Suite up to 12.2.6 Advanced Outbound Telephony access control (Nessus ID 96608 / BID-95531)
vuldb·2026-05-16·CVSS 8.2
CVE-2017-3401 [HIGH] Oracle E-Business Suite up to 12.2.6 Advanced Outbound Telephony access control (Nessus ID 96608 / BID-95531)
A vulnerability classified as critical has been found in Oracle E-Business Suite up to 12.2.6. This impacts an unknown function of the component Advanced Outbound Telephony. This manipulation causes improper access controls.
This vulnerability appears as CVE-2017-3401. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
GHSA-p3gp-c2q5-7cf9: Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface)
ghsa_unreviewed·2022-05-13
CVE-2017-3401 [HIGH] GHSA-p3gp-c2q5-7cf9: Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface)
Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15427 chromium-browser: insufficient blocking of javascript in omnibox
bugzilla·2017-12-07·CVSS 6.1
CVE-2017-15427 [MEDIUM] CVE-2017-15427 chromium-browser: insufficient blocking of javascript in omnibox
CVE-2017-15427 chromium-browser: insufficient blocking of javascript in omnibox
An insufficient blocking of javascript flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=768910
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15415 chromium-browser: pointer information disclosure in ipc call
bugzilla·2017-12-07·CVSS 6.5
CVE-2017-15415 [MEDIUM] CVE-2017-15415 chromium-browser: pointer information disclosure in ipc call
CVE-2017-15415 chromium-browser: pointer information disclosure in ipc call
A pointer information disclosure flaw was found in the IPC call component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=765512
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15417 chromium-browser: cross origin information disclosure in skia
bugzilla·2017-12-07·CVSS 5.3
CVE-2017-15417 [MEDIUM] CVE-2017-15417 chromium-browser: cross origin information disclosure in skia
CVE-2017-15417 chromium-browser: cross origin information disclosure in skia
A cross origin information disclosure flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=699028
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15412 libxml2: Use after free in xmlXPathCompOpEvalPositionalPredicate() function in xpath.c
bugzilla·2017-12-07·CVSS 8.8
CVE-2017-15412 [HIGH] CVE-2017-15412 libxml2: Use after free in xmlXPathCompOpEvalPositionalPredicate() function in xpath.c
CVE-2017-15412 libxml2: Use after free in xmlXPathCompOpEvalPositionalPredicate() function in xpath.c
An use after free flaw was found in the libXML component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=727039
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
---
Upstream details:
Bug: https://bugzilla.gnome.org/show_bug.cgi?id=783160
Patch: https://git.gnome.org/browse/libxml2/commit
Bugzilla
CVE-2017-15407 chromium-browser: out of bounds write in quic
bugzilla·2017-12-07·CVSS 8.8
CVE-2017-15407 [HIGH] CVE-2017-15407 chromium-browser: out of bounds write in quic
CVE-2017-15407 chromium-browser: out of bounds write in quic
An out of bounds write flaw was found in the QUIC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=778505
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15411 chromium-browser: use after free in pdfium
bugzilla·2017-12-07·CVSS 8.8
CVE-2017-15411 [HIGH] CVE-2017-15411 chromium-browser: use after free in pdfium
CVE-2017-15411 chromium-browser: use after free in pdfium
An use after free flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=770148
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15419 chromium-browser: cross origin leak of redirect url in blink
bugzilla·2017-12-07·CVSS 6.5
CVE-2017-15419 [MEDIUM] CVE-2017-15419 chromium-browser: cross origin leak of redirect url in blink
CVE-2017-15419 chromium-browser: cross origin leak of redirect url in blink
A cross origin leak of redirect url flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=780312
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15425 chromium-browser: url spoof in omnibox
bugzilla·2017-12-07·CVSS 6.5
CVE-2017-15425 [MEDIUM] CVE-2017-15425 chromium-browser: url spoof in omnibox
CVE-2017-15425 chromium-browser: url spoof in omnibox
An url spoof flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=756456
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15409 chromium-browser: out of bounds write in skia
bugzilla·2017-12-07·CVSS 8.8
CVE-2017-15409 [HIGH] CVE-2017-15409 chromium-browser: out of bounds write in skia
CVE-2017-15409 chromium-browser: out of bounds write in skia
An out of bounds write flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=763972
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15408 chromium-browser: heap buffer overflow in pdfium
bugzilla·2017-12-07·CVSS 8.8
CVE-2017-15408 [HIGH] CVE-2017-15408 chromium-browser: heap buffer overflow in pdfium
CVE-2017-15408 chromium-browser: heap buffer overflow in pdfium
A heap buffer overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=762374
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15424 chromium-browser: url spoof in omnibox
bugzilla·2017-12-07·CVSS 6.5
CVE-2017-15424 [MEDIUM] CVE-2017-15424 chromium-browser: url spoof in omnibox
CVE-2017-15424 chromium-browser: url spoof in omnibox
An url spoof flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=756226
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15426 chromium-browser: url spoof in omnibox
bugzilla·2017-12-07·CVSS 6.5
CVE-2017-15426 [MEDIUM] CVE-2017-15426 chromium-browser: url spoof in omnibox
CVE-2017-15426 chromium-browser: url spoof in omnibox
An url spoof flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=756735
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15422 chromium-browser: integer overflow in icu
bugzilla·2017-12-07·CVSS 6.5
CVE-2017-15422 [MEDIUM] CVE-2017-15422 chromium-browser: integer overflow in icu
CVE-2017-15422 chromium-browser: integer overflow in icu
An integer overflow flaw was found in the ICU component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=774382
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
---
Created icu tracking bugs for this issue:
Affects: fedora-all [bug 1526891]
Created mingw-icu tracking bugs for this issue:
Affects: epel-7 [bug 1526889]
---
Create
Bugzilla
CVE-2017-15418 chromium-browser: use of uninitialized value in skia
bugzilla·2017-12-07·CVSS 4.3
CVE-2017-15418 [MEDIUM] CVE-2017-15418 chromium-browser: use of uninitialized value in skia
CVE-2017-15418 chromium-browser: use of uninitialized value in skia
An use of uninitialized value flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=765858
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15423 chromium-browser: issue with spake implementation in boringssl
bugzilla·2017-12-07·CVSS 5.3
CVE-2017-15423 [MEDIUM] CVE-2017-15423 chromium-browser: issue with spake implementation in boringssl
CVE-2017-15423 chromium-browser: issue with spake implementation in boringssl
An issue with spake implementation flaw was found in the BoringSSL component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=778101
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15420 chromium-browser: url spoofing in omnibox
bugzilla·2017-12-07·CVSS 6.5
CVE-2017-15420 [MEDIUM] CVE-2017-15420 chromium-browser: url spoofing in omnibox
CVE-2017-15420 chromium-browser: url spoofing in omnibox
An url spoofing flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=777419
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15413 chromium-browser: type confusion in webassembly
bugzilla·2017-12-07·CVSS 8.8
CVE-2017-15413 [HIGH] CVE-2017-15413 chromium-browser: type confusion in webassembly
CVE-2017-15413 chromium-browser: type confusion in webassembly
A type confusion flaw was found in the WebAssembly component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=766666
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15410 chromium-browser: use after free in pdfium
bugzilla·2017-12-07·CVSS 8.8
CVE-2017-15410 [HIGH] CVE-2017-15410 chromium-browser: use after free in pdfium
CVE-2017-15410 chromium-browser: use after free in pdfium
An use after free flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=765921
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
Bugzilla
CVE-2017-15416 chromium-browser: out of bounds read in blink
bugzilla·2017-12-07·CVSS 6.5
CVE-2017-15416 [MEDIUM] CVE-2017-15416 chromium-browser: out of bounds read in blink
CVE-2017-15416 chromium-browser: out of bounds read in blink
An out of bounds read flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=779314
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401
2017-01-27
Published